Severity
3.8LOW
EPSS
0.1%
top 83.05%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 3
Latest updateMay 24

Description

An exposure of sensitive information to an unauthorized actor [CWE-200] vulnerability in FortiManager 7.0.1 and below, 6.4.6 and below, 6.2.x, 6.0.x, 5.6.0 may allow a FortiGate user to see scripts from other ADOMS.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:NExploitability: 2.0 | Impact: 2.7

Affected Packages2 packages

NVDfortinet/fortimanager6.4.06.4.6+4
CVEListV5fortinet/fortinet_fortimanagerFortiManager 7.0.1 and below, 6.4.6 and below, 6.2.x, 6.0.x, 5.6.0

🔴Vulnerability Details

2
GHSA
GHSA-c7pf-4hv4-q9h9: An exposure of sensitive information to an unauthorized actor [CWE-200] vulnerability in FortiManager 72022-05-24
CVEList
CVE-2021-36192: An exposure of sensitive information to an unauthorized actor [CWE-200] vulnerability in FortiManager 72021-11-03

📋Vendor Advisories

1
Fortinet
An exposure of sensitive information to an unauthorized actor [CWE-200] vulnerability in FortiManager 7.0.1 and below, 6...2021-11-03
CVE-2021-36192 (LOW CVSS 3.8) | An exposure of sensitive informatio | cvebase.io